Files
algo/tests/test-wireguard-async.yml
T
ba7297268a Simplify codebase: modernize loops, split templates, improve CI (#14889)
* Simplify codebase: modernize loops, split templates, improve CI

This PR consolidates several simplification phases:

## Ansible Modernization
- Modernize `with_items` to `loop` across ~50 task files
- Add OS detection facts (is_ubuntu, os_family_lowercase)
- Condense inline YAML syntax where appropriate

## Template Splitting
- Split 568-line dnscrypt-proxy.toml.j2 into focused partials:
  - global.toml.j2 (core settings)
  - sources.toml.j2 (resolver sources)
  - filters.toml.j2 (blocking rules)
  - cache.toml.j2 (caching config)

## CI Workflow Improvements
- Create setup-algo composite action for shared CI setup
- Re-enable integration tests with health checks
- Fix smart-tests.yml silent lint failures (remove || true)
- Use env variables for GitHub SHAs (security)

## server.yml Async Simplification
- Reorganize VPN service configuration with clear sections
- Add performance_parallel_services toggle
- Simplify status display from json_query to inline conditionals
- Keep services explicit for readability

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* Fix with_items to loop conversion: preserve list flattening

with_items automatically flattens nested lists, but loop does NOT.
The mechanical conversion broke iteration over list variables.

Wrong:
  loop:
    - "{{ users }}"  # ['alice', 'bob'] treated as ONE item

Fixed:
  loop: "{{ users }}"  # Iterates over alice, bob correctly

For combined lists (users + server):
  loop: "{{ users + [IP_subject_alt_name] }}"

Fixes IPsec certificate generation creating files named literally
'['alice', 'bob'].key' instead of separate alice.key and bob.key.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* Fix integration test: use strongswan-starter service name on Ubuntu 20.04+

The StrongSwan service is named 'strongswan-starter' on Ubuntu 20.04+,
not 'strongswan'. The test was checking the wrong service name, causing
false failures even when StrongSwan was actually running.

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

* Fix IPsec path issues: remove trailing slashes and fix test paths

1. Remove trailing slashes from ipsec_config_path and ipsec_pki_path
   in roles/strongswan/defaults/main.yml (causes double slashes)

2. Fix integration test to check correct subdirectories:
   - .p12 files are in ipsec/manual/
   - .mobileconfig files are in ipsec/apple/

3. Fix strongswan service name check (strongswan-starter on Ubuntu 20.04+)

🤖 Generated with [Claude Code](https://claude.com/claude-code)

Co-Authored-By: Claude <noreply@anthropic.com>

---------

Co-authored-by: Claude <noreply@anthropic.com>
2025-11-28 04:28:59 -05:00

87 lines
2.8 KiB
YAML

---
# Test WireGuard async result structure handling
# This simulates the async_status result structure to verify our fix
- name: Test WireGuard async result handling
hosts: localhost
gather_facts: no
vars:
# Simulate the actual structure that async_status with with_items returns
# This is the key insight: async_status results contain the original item info
mock_wg_genkey_results:
results:
- item: "user1" # This comes from the original wg_genkey.results item
stdout: "mock_private_key_1" # This is the command output
changed: true
rc: 0
failed: false
finished: true
- item: "10.10.10.1" # This comes from the original wg_genkey.results item
stdout: "mock_private_key_2" # This is the command output
changed: true
rc: 0
failed: false
finished: true
wireguard_pki_path: "/tmp/test-wireguard-pki"
tasks:
- name: Create test directories
file:
path: "{{ item }}"
state: directory
mode: '0700'
loop:
- "{{ wireguard_pki_path }}/private"
- "{{ wireguard_pki_path }}/preshared"
- name: Test private key saving (using with_items like the actual code)
copy:
dest: "{{ wireguard_pki_path }}/private/{{ item.item }}"
content: "{{ item.stdout }}"
mode: "0600"
when: item.changed
loop: "{{ mock_wg_genkey_results.results }}"
- name: Verify files were created correctly
stat:
path: "{{ wireguard_pki_path }}/private/{{ item }}"
register: file_check
loop:
- "user1"
- "10.10.10.1"
- name: Assert files exist
assert:
that:
- item.stat.exists
- item.stat.mode == "0600"
msg: "Private key file should exist with correct permissions"
loop: "{{ file_check.results }}"
- name: Verify file contents
slurp:
src: "{{ wireguard_pki_path }}/private/{{ item }}"
register: file_contents
loop:
- "user1"
- "10.10.10.1"
- name: Assert file contents are correct
assert:
that:
- (file_contents.results[0].content | b64decode) == "mock_private_key_1"
- (file_contents.results[1].content | b64decode) == "mock_private_key_2"
msg: "File contents should match expected values"
# Test the error handling path too
- name: Test error condition handling
debug:
msg: "Would display error for {{ item.item }}"
when: item.rc is defined and item.rc != 0
loop: "{{ mock_wg_genkey_results.results }}"
# This should not trigger since our mock data has rc: 0
- name: Cleanup test directory
file:
path: "{{ wireguard_pki_path }}"
state: absent